Home / Companies / Evervault / Blog / Post Details
Content Deep Dive

How we built Enclaves: Egress Networking

Blog post from Evervault

Post Details
Company
Date Published
Author
Hannah Neary
Word Count
1,636
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Evervault has introduced Enclaves, designed to facilitate the deployment of applications within a Confidential Computing environment, specifically using AWS Nitro Enclaves. This initiative addresses the initial limitations of Nitro Enclaves, which lack inherent networking capabilities, by enabling optional egress traffic to support a wider variety of applications, such as card payments and blockchain transactions. Initially, the development team experimented with DNS spoofing and SNI-based routing to manage egress networking but found these methods insufficient for scalability and flexibility, prompting a redesign. By leveraging iptables, Evervault refined the egress networking process, allowing traffic redirection without binding to multiple ports and removing the dependency on SNI, thus supporting a broader range of protocols. The new approach also involves caching DNS results to handle dynamic IP changes and implements domain and IP allowlisting to prevent potential supply chain attacks. Overall, these improvements have resulted in a more extensible, user-friendly system that does not confuse users with DNS spoofing or waste resources, while also supporting a wider range of use cases.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.